Impact
An out‑of‑bounds read in a kernel component responsible for processing disk images was addressed with improved bounds checking. The flaw, mitigated in recent releases by stricter bounds checking, can be triggered by mounting a specially crafted volume. When exploited, the read may exceed the intended buffer boundaries, allowing an attacker to read arbitrary kernel memory, corrupt critical data structures, or force the operating system to terminate unexpectedly. These effects compromise confidentiality, integrity, and availability at the kernel level and could provide a foothold for further privilege escalation.
Affected Systems
Apple’s macOS is impacted by this issue. The vulnerability exists in releases predating macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, and macOS Tahoe 26.6. Any system running an earlier version of these operating systems that processes disk images may be susceptible.
Risk and Exploitability
The CVSS score is 9.8, and the EPSS score is < 1%, indicating a very low, but non‑zero exploitation probability. However, the weakness involves kernel memory corruption, which is treated with high severity. Attackers would need to deliver a malicious disk image and mount it, suggesting the vector is local or requires privileged user interaction; remote exploitation is less likely unless a patch or user script triggers mounting. The lack of CISA KEV marking indicates no confirmed public exploitation as of now, but the potential for privilege escalation or denial of service warrants careful monitoring.
OpenCVE Enrichment